CFCA self-reported cross-signed certificate missing required EKU extension
CFCA reported a compliance incident involving a cross-signed certificate created when a multipurpose root certificate was used to cross-sign a dedicated root certificate. CFCA said the resulting cross-signed certificate did not include the Extended Key Usage (EKU) extension, which it stated was required in this situation. The report cites CCADB Section 6.3 on cross-certification across PKI hierarchies and notes that the dedicated root’s subordinate CAs correctly assert EKU consistent with the dedicated purpose. The bug was opened by CFCA itself as a preliminary incident report, and the thread shown does not include a final resolution. The case remains assigned to CFCA contact d**********o@cfca.com.cn.
- CFCA created a cross-signed certificate from a multipurpose root to a dedicated root without including the EKU extension.
- China Financial Certification Authority (CFCA) — CFCA filed a preliminary incident report stating that the cross-signed certificate lacked the required EKU extension and identified the disclosure as self-reported.